14 ms·
This is an interesting part to me: "[T]he new order[0] adds more provisions to protect consumers in the future: ... Twitter must provide multi-factor authentica
by techsupporter 4y ago
This is an interesting part to me: "[T]he new order[0] adds more provisions to protect consumers in the future: ... Twitter must provide multi-factor authentication options that don’t require people to provide a phone number."
I would like to see this be a more broad-based rule. No, I am not moved by "SMS is easy" or "getting a number that can receive SMS is harder for scammers to do in bulk." If you must, give users the choice but not the obligation to hand over a mobile number.
0 - https://www.ftc.gov/legal-library/browse/cases-proceedings/2023062-twitter-inc-us-v https://www.ftc.gov/legal-library/browse/cases-proceedings/2...
- latchkey 4y agoThey already provide these options today.
- falcolas 4y agoIt's a precedent. This isn't just about Twitter; there are many who do not offer such options.
- zaroth 4y agoI don’t think it has any applicability to anyone beyond Twitter. Maybe it’s a precedent that the FTC will tell you to add non-SMS 2-factor if you are misusing the SMS factor for advertising, but that’s a pretty limited precedent!
- tomnipotent 4y agoIt emboldens prosecutors and DA's and makes conversations around going after other bad actors more tenable.
- gabereiser 4y agoTo further expand on this. 2FA should not rely on SMS at all. It should be an option but not the default one. An Authenticator app should be the default. I know we assume everyone has a cell phone but that’s not the case.
- fron 4y agoWebAuthn should be the default
- autoexec 4y agoAuthenticator apps aren't much better. Look at their privacy policies. Installing Microsoft Authenticator means giving them your location data 24/7 and allows the to collect even more data on you than giving Twitter your phone number did. Do you really think they aren't going to use that data for anything else? I don't believe that anymore than I believed Twitter. Personally, I'd rather deal with the hassle of carrying around multiple hardware tokens than give companies a continuous stream of data about my personal life to use against me.
- blueblimp 4y agoI use Microsoft Authenticator on iOS, and it doesn't use location. (I didn't even need to deny it--it didn't ask for it.)
- crossroadsguy 4y agoThey do ask on Android it seems. Not sure if this text is common across all apps seeking location permission. > Optional App functionality, Fraud prevention, security and compliance However I’m not surprised such apps keeping double standards between iOS and Androids. Apple spanks (or spanks harder) the apps that ask permissions frivolously or block functionality behind permissions unnecessarily just to collect data. For e.g I use TrueCaller on iOS without giving Contacts permission, but on Android the app features are blocked without it. Not sure of now but earlier Ola/Uber didn’t work on Android without location permission but on iOS they did and still do. Many such examples.
- C4K3 4y agoYou don't have to use microsoft authenticator. TOTP is a big step up from SMS and most/good apps won't violate your privacy.
- viraptor 4y ago
- li2uR3ce 4y agoAlso SMS not nearly reliable enough. You should have alternatives for that reason alone. My cell carrier was blocking many SMS verification messages for a good two months. It caused me all kinds of problems when my credit union merged with another and I had to change account numbers all over the place. Many had the option of using an email address, but there were quite a few that it was SMS or play find the human on the 800 number.
- prirun 4y agoUnrelated to Twitter, but your post reminded me that consumer should also have an independent "account number" for lack of a better word that belongs to the user, like a telephone number. Electronic payments would come out of this personal account number and be forwarded to whatever institution(s) the person wants. Then changing banks would be as easy as changing phone carriers.
- gigel82 4y agoI was overseas and my provider (Cricket) doesn't have roaming so I usually pick up a cheap prepaid SIM locally. I didn't enable 2FA on Uber but it insisted on sending me a code via SMS (of course, to my inaccessible US number). That was incredibly stupid and shortsighted. Meanwhile, all services that were set up for Authenticator MFA worked just fine over the European carrier's LTE.
- l72 4y agoI also tend to purchase a prepaid SIM while overseas, and ran into a bunch of issues paying for bills at bars/restaurants using their website or mobile apps, as my credit card was doing a second layer of authentication through Mastercard's Verification and would only send me a code via SMS! It is crazy that my capitalone mastercard wouldn't allow me to do the validation through my capitalone app!
- BizarroLand 4y agoNext time, use an app like pushbullet that will forward your text messages to you. It's a huge security risk since if pushbullet or whatever gets hacked then the hackers would get all of your access, but for a short term utility like ensuring that you have connectivity it may be well worth it.
- danrocks 4y agoThis. It drives me crazy that the most critical service I use, Vanguard, still requires SMS for 2FA. It's a pre-requisite for using a yubikey. It makes no sense.
- exabrial 4y agoI hope Authy, Apple, Twilio, and many others take note.
- deleted 4y ago[deleted]
- me_me_mu_mu 4y agoThis. Allow email and authenticator app options. It is also frustrating that voip numbers don't work in some auth scenarios.
- Thorrez 4y ago>Twitter must provide multi-factor authentication options that don’t require people to provide a phone number." Hmm. That might be difficult. I always thought the reason Twitter required phone numbers was to stop spam accounts from being created. So a phone number is basically acting like an expensive captcha. This order seems to be saying Twitter needs to stop requiring phone numbers. That might lead to an increase in spam accounts.